Skip to content

Merge the feature branch into aos/cutover - #491

Merged
SaladDay merged 14 commits into
aos/cutoverfrom
aos/cutover-sync-2
Oct 7, 2026
Merged

SaladDay merged 14 commits into
aos/cutoverfrom
aos/cutover-sync-2

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Merges feature/agent-outside-sandbox (c1abd12: #481 and the #483 sync of main 6fc76ad) into aos/cutover after PR1 (#479).

Resolution keeps PR1's assignment model for every surviving Session operation and every deletion from both sides. The five dispatch tests PR1 deleted cover live behavior and are ported onto the assignment helpers. Core deliver takes the feature side's runID/input parameters and threads the assignment through every send.

Checks after the merge commit: gofmt, vet in all three modules, darwin/windows daemon builds, focused tests for proto, dispatch, cli, agent, wireconformance, runtimegateway, execution and api, the full Core integration suite (401s), -race -count=50 on the 18 ported concurrent tests, and make check-names check-docs check-ci.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

SaladDay and others added 14 commits October 7, 2026 13:14
…#468)

Core sends only model, system_prompt, model_provider and harness_config
in agent_options. Delete the adapter keys no Core path produces: codex
override_system_prompt, reasoning_summary, mode, mcp_servers,
enable_features, disable_features, skills and the controls copied into
web_search/model_verbosity; mcode mode, override_system_prompt, skills,
plugins and mcp_servers. Codex reads ExecutionControls directly. The
managed Skill installer, the Runtime capability-download and skill-upload
wrappers, the Runtime capability-context flags and the no-op feature
preference removals go with them.

Dispatch now rejects any other agent_options key, and an execution
preparation with neither or both of local_environment and
disable_execution_environment, with unsupported_configuration before a
factory runs. claude_sdk's own unknown-key branch is unreachable and
removed. agent.ManagedSkillsRoot becomes StateDir, its only remaining
use.
Core never sets workspace_authoring and always sends strict_resume and
observe_tool_observations as true, so the Runtime carried code paths that
no Core request reaches. Delete them and keep only the behavior Core uses:

- Workspace authoring: the proto messages and socket variable, the
  WorkspaceAuthoring request field and capability, the daemon authoring
  bridge, its CLI wiring and companion PATH helper, the env agent option
  that only the bridge injected, and Core's capability copy and
  authoring_request rejection case.
- strict_resume: resume and recovery are always strict; mcode always runs
  its protected execution profile.
- observe_tool_observations: adapters always attach the neutral
  observation to tool_call frames.
- Codex and the shared StateDir no longer derive legacy state keys from
  the conversation or run; an empty agent state key is rejected.
- clirunner always owns the child's process group (a Job object on
  Windows), because every caller now requests it.

The Core-Runtime protocol doc, Harness onboarding, CONTRIBUTING and the
Claude SDK adapter README drop the deleted fields and features.
* fix: make installation retries safe and predictable

* fix: share installation log cleanup on every retry

* fix: make retry preparation atomic and preserve running images

* fix: complete installer preparation before publishing state

* fix: publish node configuration atomically
* Remove the unserved daemon pairing path and runtimecrypto

`oac-daemon connect --url --token` posted to /api/v1/runtimes/pair, which
Core does not serve and no contract documents, so the path always failed.
Its envelope encryption was never wired: Core never stored or used
runner_public_key, and SealForRuntime had no caller outside its fixture
generator.

Daemon credentials come from a Provider bootstrap file, self-hosted
Environment enrollment or the oac-core-device profile, all unchanged.

- Delete pair.go, the inline pairing flags, their environment handoff and
  their tests.
- Delete internal/runtimecrypto; golang.org/x/crypto is no longer required.
- auth: drop the pairing-only Profile fields and Save, which no longer has
  a production caller; the not-found error points to oac-core-device.
- daemonize: drop ReExecOptions.ExtraEnv, which only carried the pairing
  token to the background child.
- paths: drop EnsureProfileDir, whose only caller was auth.Save.
- Reword comments and docs that described pairing.

* Remove obsolete Parsar integration naming guidance

* docs: sync bootstrap translation after pairing removal

---------

Co-authored-by: saladday <1203511142@qq.com>
Core starts every Run through execution_prepare and execution_start, so
the prompt_request frame, its daemon path and Core's unprepared delivery
branch had no caller.

- Delete proto.TypePromptRequest and its protocol rows; the daemon drops
  the frame as an unknown type. PromptRequestPayload stays as the
  execution_prepare configuration.
- Delete the daemon prompt path (prompt.go, output.go, the retained idle
  session pool, the completion barrier and the unprepared cancel and
  shutdown branches). A Run's session is now an agent.Turn, so durable
  steering support is enforced by type.
- Core deliver takes the prepared handle, Run ID and input explicitly.
- Delete ConversationID and ReleaseOnCompletion; WorkspaceReadOnly alone
  marks a read-only preparation.
- validateExecutionEnvironment owns the exactly-one local_environment /
  disable_execution_environment rule.
- Port the dispatch tests that cover behavior execution_start keeps to
  shared execution_prepare/execution_start helpers.
* Run environment none and stdio MCP in the Codex view

* Run environment none and stdio MCP in the Claude view

* Run environment none and stdio MCP in the MiniMax Code view

* Say that Codex keeps its native project trust in the view
Shutdown marks every executor invalid but closes only owners without a
Run, leaving a running owner's close to its prepared release. The release
reads r.closed and owner.invalid once, before joining operations and
retiring the Run. When Shutdown took the lock after that reuse decision
and before the Run let go of the owner, nobody closed the executor: it
stayed in r.executors with no close in flight, and Shutdown reported
"cleanup unconfirmed" for a healthy native executor. Device shutdown
has the same window and left the owner permanently invalid.

When the release retires an owner that was invalidated without a close,
start the close under shutdownWG so Shutdown waits for it. Report an
executor that remains without a close error as "cleanup has not
settled" instead of wrapping a nil error.
# Conflicts:
#	Makefile
#	apps/daemon/internal/agent/claudesdk/cancellation_live_linux_test.go
#	apps/daemon/internal/agent/claudesdk/commands_session_test.go
#	apps/daemon/internal/agent/claudesdk/executor.go
#	apps/daemon/internal/agent/claudesdk/executor_live_linux_test.go
#	apps/daemon/internal/agent/claudesdk/functions_test.go
#	apps/daemon/internal/agent/claudesdk/live_linux_test.go
#	apps/daemon/internal/agent/claudesdk/options.go
#	apps/daemon/internal/agent/claudesdk/preparation_test.go
#	apps/daemon/internal/agent/claudesdk/session.go
#	apps/daemon/internal/agent/claudesdk/workspace_live_linux_test.go
#	apps/daemon/internal/agent/clirunner/process.go
#	apps/daemon/internal/agent/codex/declaration_test.go
#	apps/daemon/internal/agent/codex/environment.go
#	apps/daemon/internal/agent/codex/execution_controls_test.go
#	apps/daemon/internal/agent/codex/executor_native_test.go
#	apps/daemon/internal/agent/codex/harness_config_test.go
#	apps/daemon/internal/agent/codex/mcp_config.go
#	apps/daemon/internal/agent/codex/mcp_config_test.go
#	apps/daemon/internal/agent/codex/mcp_http_bearer_test.go
#	apps/daemon/internal/agent/codex/mcp_http_test.go
#	apps/daemon/internal/agent/codex/mcp_required_test.go
#	apps/daemon/internal/agent/codex/model_route_test.go
#	apps/daemon/internal/agent/codex/model_verbosity_test.go
#	apps/daemon/internal/agent/codex/options.go
#	apps/daemon/internal/agent/codex/options_test.go
#	apps/daemon/internal/agent/codex/preparation.go
#	apps/daemon/internal/agent/codex/preparation_helpers_test.go
#	apps/daemon/internal/agent/codex/provider_config_test.go
#	apps/daemon/internal/agent/codex/session_plan.go
#	apps/daemon/internal/agent/codex/session_policy_test.go
#	apps/daemon/internal/agent/codex/skills.go
#	apps/daemon/internal/agent/codex/skills_test.go
#	apps/daemon/internal/agent/harness.go
#	apps/daemon/internal/agent/mcode/declaration.go
#	apps/daemon/internal/agent/mcode/declaration_test.go
#	apps/daemon/internal/agent/mcode/execution.go
#	apps/daemon/internal/agent/mcode/executor.go
#	apps/daemon/internal/agent/mcode/executor_native_test.go
#	apps/daemon/internal/agent/mcode/harness_config_test.go
#	apps/daemon/internal/agent/mcode/model_provider_test.go
#	apps/daemon/internal/agent/mcode/native_history_test.go
#	apps/daemon/internal/agent/mcode/native_test.go
#	apps/daemon/internal/agent/mcode/options.go
#	apps/daemon/internal/agent/mcode/options_test.go
#	apps/daemon/internal/agent/mcode/preparation_test.go
#	apps/daemon/internal/agent/mcode/session.go
#	apps/daemon/internal/agent/mcode/session_test.go
#	apps/daemon/internal/agent/mcode/workspace.go
#	apps/daemon/internal/agent/registry.go
#	apps/daemon/internal/agent/runtime_paths.go
#	apps/daemon/internal/agent/runtime_paths_test.go
#	apps/daemon/internal/auth/store.go
#	apps/daemon/internal/auth/store_test.go
#	apps/daemon/internal/cli/claude_sdk_live_linux_test.go
#	apps/daemon/internal/cli/connect.go
#	apps/daemon/internal/cli/connect_bootstrap_test.go
#	apps/daemon/internal/cli/connect_environment.go
#	apps/daemon/internal/cli/preparation_test.go
#	apps/daemon/internal/cli/root.go
#	apps/daemon/internal/cli/status.go
#	apps/daemon/internal/daemonize/fork_test.go
#	apps/daemon/internal/dispatch/executor.go
#	apps/daemon/internal/dispatch/functions_native_test.go
#	apps/daemon/internal/dispatch/preparation.go
#	apps/daemon/internal/dispatch/preparation_test.go
#	apps/daemon/internal/dispatch/prompt.go
#	apps/daemon/internal/dispatch/router_test.go
#	apps/daemon/internal/dispatch/shutdown.go
#	apps/daemon/internal/localworkspace/binding.go
#	apps/daemon/internal/localworkspace/binding_test.go
#	apps/daemon/internal/paths/paths.go
#	apps/daemon/internal/transport/ws.go
#	contracts/agents-api/harness-onboarding.md
#	contracts/agents-api/zh/harness-onboarding.md
#	docs/runtime-protocol.md
#	docs/zh/maintainers.md
#	docs/zh/runtime-protocol.md
#	internal/agentdaemon/proto/outbound.go
#	internal/agentdaemon/proto/preparation.go
#	internal/agentdaemon/proto/workspace_read_preparation.go
#	packages/claude-sdk-adapter/README.md
#	scripts/ci_plan.py
#	scripts/name-allowlist.json
#	services/core/deploy/codex/README.md
#	services/core/internal/execution/request.go
#	services/core/internal/runtimegateway/auth.go
#	services/core/internal/runtimegateway/handler.go
#	services/core/internal/runtimegateway/mcp_bearer_live_linux_test.go
#	services/core/internal/runtimegateway/routes.go
#	services/core/tests/integration/dispatch_test.go
Merge main into the agent-outside-sandbox branch
…nto aos/cutover-sync-2

# Conflicts:
#	apps/daemon/internal/agent/claudesdk/cancellation_live_linux_test.go
#	apps/daemon/internal/agent/claudesdk/executor_live_linux_test.go
#	apps/daemon/internal/agent/claudesdk/functions_test.go
#	apps/daemon/internal/agent/claudesdk/live_linux_test.go
#	apps/daemon/internal/agent/codex/options.go
#	apps/daemon/internal/agent/codex/session_policy_test.go
#	apps/daemon/internal/agent/mcode/options.go
#	apps/daemon/internal/cli/claude_sdk_live_linux_test.go
#	apps/daemon/internal/cli/connect_cleanup_test.go
#	apps/daemon/internal/dispatch/cancellation.go
#	apps/daemon/internal/dispatch/cancellation_test.go
#	apps/daemon/internal/dispatch/capability_admission_test.go
#	apps/daemon/internal/dispatch/environment_test.go
#	apps/daemon/internal/dispatch/executor.go
#	apps/daemon/internal/dispatch/executor_handoff_test.go
#	apps/daemon/internal/dispatch/executor_test.go
#	apps/daemon/internal/dispatch/functions_native_test.go
#	apps/daemon/internal/dispatch/functions_test.go
#	apps/daemon/internal/dispatch/local_directory_test.go
#	apps/daemon/internal/dispatch/mcp_http_test.go
#	apps/daemon/internal/dispatch/optional_interactions_test.go
#	apps/daemon/internal/dispatch/preparation.go
#	apps/daemon/internal/dispatch/preparation_start.go
#	apps/daemon/internal/dispatch/preparation_test.go
#	apps/daemon/internal/dispatch/receipt_order_test.go
#	apps/daemon/internal/dispatch/receipt_shutdown_test.go
#	apps/daemon/internal/dispatch/router.go
#	apps/daemon/internal/dispatch/router_test.go
#	apps/daemon/internal/dispatch/shutdown.go
#	apps/daemon/internal/dispatch/steering.go
#	apps/daemon/internal/dispatch/steering_lifetime_test.go
#	apps/daemon/internal/dispatch/steering_test.go
#	apps/daemon/internal/dispatch/suspend_test.go
#	apps/daemon/internal/dispatch/workspace_write.go
#	apps/daemon/internal/wireconformance/wire_test.go
#	contracts/agents-api/zh/harness-onboarding.md
#	docs/runtime-protocol.md
#	docs/zh/getting-started/install.md
#	docs/zh/getting-started/operations.md
#	docs/zh/getting-started/self-hosted.md
#	docs/zh/runtime-protocol.md
#	internal/agentdaemon/proto/envelope.go
#	internal/agentdaemon/proto/outbound.go
#	internal/agentdaemon/proto/prototest/wire.go
#	services/core/internal/execution/delivery.go
#	services/core/internal/execution/directory_preparation.go
#	services/core/internal/execution/executor_preparation.go
#	services/core/internal/execution/preparation.go
#	services/core/internal/runtimegateway/cancellation_test.go
#	services/core/internal/runtimegateway/mcp_bearer_live_linux_test.go
#	services/core/internal/runtimegateway/session_test.go
@SaladDay
SaladDay merged commit a0c5d47 into aos/cutover Oct 7, 2026
1 check passed
@SaladDay
SaladDay deleted the aos/cutover-sync-2 branch October 7, 2026 13:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants