Skip to content

Sync main 7bba93ae into the cutover - #503

Merged
SaladDay merged 20 commits into
aos/cutoverfrom
aos/cutover-sync-3
Oct 7, 2026
Merged

SaladDay merged 20 commits into
aos/cutoverfrom
aos/cutover-sync-3

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Merges aos/main-sync-3 (main 7bba93a through the feature branch) into aos/cutover, on top of PR2 (#496). It also includes one test commit: the registered Claude SDK and MCP bearer live tests now send the Session's ModelProvider, because preparation requires one.

Local checks:

  • gofmt is clean.
  • go vet passes for the root, daemon and Core modules.
  • Darwin and windows daemon builds pass.
  • make check-names check-docs check-ci check-openapi check-harness-catalog check-sqlc pass.
  • node --test passes.
  • The same focused test set as the feature sync passes.
  • Core integration is running on this head.

Live tests:

  • The first real MiniMax Turn of TestLiveMCPBearerGatewayColdContinuation completes through the Session's provider.
  • Its cold-continuation step still fails, and that is not caused by this merge. The test sends execution_release after the Run has started and waits for released. Under the execution admission rules (docs/runtime-protocol.md), releasing after start does not retire the Executor. The step is tracked as a follow-up.
  • TestLiveRegisteredClaudeSDK was not run live.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

SaladDay and others added 20 commits October 7, 2026 20:07
…476)

* feat: share Core installation across Linux macOS and Windows

* fix: recover interrupted staging and qualify native platforms

* fix: use native Web base images and one Compose startup

* test: exercise the PowerShell launcher with native oac

* test: share launcher fixtures across PowerShell script scopes

* docs: align installation guidance with shared platform support

* docs: correct secret mounts and installation locking

* docs: clarify native management command invocation
Runs start only through the Executor, so agent.Factory, Runtime.Session, Registry.Resolve, the factories map and each adapter's direct-call factory had no production caller. RegisterKind now registers only the descriptor and model configuration, and Register rejects factories on an unavailable runtime. Code that only the factories reached is deleted, and the adapter tests run through the Executor path.
* ci: review documentation consistency and ownership

* ci: split reviews and send one combined Feishu report
Every Harness now runs unattended; a human in the loop goes only through
function tools and requires_action, as in the pinned Agents API.

- mcode advertises no elicitation and answers session/request_permission
  with the ACP cancelled outcome, which mcode treats as a denial; other
  client methods get -32601.
- codex disables its blocking tools.experimental_request_user_input tool;
  under approval policy never it settles MCP elicitation itself, and any
  other server request gets the client's method-not-found reply. The
  approval policy and sandbox unions collapse to constants.
- Delete permission_request, permission_cancel, permission_decision,
  prompt_for_user_choice, prompt_for_user_choice_decision, device_shutdown,
  the Permissions capability, the responder interfaces, the daemon
  interaction routing, the gateway interaction indexes and the
  interaction_not_supported diagnostic.
- interaction_decision_ack stays for function results and cancellation;
  the daemon's applied-result replay now serves function results only.

Bumps the Core–Runtime protocol to 0.12.0, which also covers the earlier
agent_options, request-field and prompt_request removals.
…ecisions (#488)

* Bound the Link relay's resources, attachments and closures

The relay held serve peers, attachments and pending AttachmentClosed
events without limit, so peers could grow Core's memory without bound.
Each now takes a slot at admission, before the Authority is consulted,
and a Hello or Open beyond capacity is refused with LimitExceeded and
leaves no state:

- A resource holds one of 4096 slots from the serve Hello that first
  names it while the relay holds anything for it: its serve peer, a
  Hello being decided, an attachment or an unwritten event. Its
  generation, serve peer and events now live in one record, so the
  generation map no longer grows with every resource ever served.
- An attachment holds one of 16384 slots until it is closed and its
  AttachmentClosed events are written or discarded, so pending events
  are bounded by construction.
- An attach link holds one of 4096 slots until it ends.

RevokeResource now discards the events its revoked serve peer could
not read, since its authority is withdrawn and it cannot reconnect;
otherwise every destroyed sandbox would keep its slots. An Open of an
attachment that closes while the Authority decides fails with
LeaseExpired instead of recreating it without a slot.

* Bound the Link relay's pending Hellos and Opens

A serve Hello now takes one of two Hello slots of its resource until it
is decided, so later Hellos for a held resource no longer wait on the
Authority without limit. An Open takes a stream slot of its attach link
before the Authority decides and keeps it until its decision ends, even
when the peer resets the stream, and an attach link keeps its slot until
every stream and renewal it carried has finished. An Open whose
attachment closes while it is decided now fails with LeaseExpired even
when another Open has created an attachment under the same ID since.
# Conflicts:
#	apps/daemon/internal/agent/claudesdk/cancellation_live_linux_test.go
#	apps/daemon/internal/agent/claudesdk/execution_controls_test.go
#	apps/daemon/internal/agent/claudesdk/readiness_test.go
#	apps/daemon/internal/agent/claudesdk/unsupported_test.go
#	apps/daemon/internal/agent/claudesdk/workspace_live_linux_test.go
#	apps/daemon/internal/agent/codex/declaration_test.go
#	apps/daemon/internal/agent/codex/options.go
#	apps/daemon/internal/agent/codex/options_test.go
#	apps/daemon/internal/agent/codex/preparation.go
#	apps/daemon/internal/agent/codex/prepared.go
#	apps/daemon/internal/agent/codex/subagent_observations_test.go
#	apps/daemon/internal/agent/contract_declarations_test.go
#	apps/daemon/internal/agent/harness.go
#	apps/daemon/internal/agent/mcode/environment_mcp_test.go
#	apps/daemon/internal/agent/mcode/options.go
#	apps/daemon/internal/agent/mcode/options_test.go
#	apps/daemon/internal/agent/mcode/preparation.go
#	apps/daemon/internal/agent/mcode/preparation_test.go
#	apps/daemon/internal/agent/mcode/session.go
#	apps/daemon/internal/agent/registry.go
#	apps/daemon/internal/cli/preparation_test.go
#	apps/daemon/internal/dispatch/interaction_decisions.go
#	apps/daemon/internal/dispatch/local_directory_test.go
#	apps/daemon/internal/dispatch/preparation_test.go
#	apps/daemon/internal/dispatch/router.go
#	contracts/agents-api/harness-onboarding.md
#	contracts/agents-api/zh/harness-onboarding.md
#	docs/runtime-protocol.md
#	docs/zh/configuration.md
#	docs/zh/maintainers.md
#	docs/zh/runtime-protocol.md
#	internal/agentdaemon/proto/outbound.go
#	services/core/internal/runtimegateway/mcp_bearer_live_linux_test.go
Merge main into the agent-outside-sandbox branch
* refactor(api): generate public contracts from pinned official OpenAPI

* test(api): validate OpenAPI 3.1 responses and preserve package rejection

* chore(api): remove unused Swagger parser dependency

* fix(api): derive web search union serialization from the official schema

* fix(api): preserve stored search items during public schema migration
* Delete the adapter Prepared path

Every Run starts through Executor.StartTurn, and read-only preparations
are served from the bound local workspace, so the adapter Prepared
surface and its registered preparation factories have no production
caller. Port the deletion from the agent-outside-sandbox branch with the
same shape: delete agent.Prepared, PreparedCancellation,
PreparationFactory, Runtime.Preparation, RegisterPreparation and
ResolvePreparation, the Codex, Claude SDK and MiniMax Code preparation
factories, and the Claude session's unused drain. Adapters declare
WorkspaceReadPreparation beside LocalEnvironment and dispatch readies the
local preparation directly. Delete the unenforced Runtime initialization
network field and bump the protocol version.

Delete the Codex one-shot start path (Prepared.start and Session.run),
which only tests reached, and port its behaviour tests to
Executor.StartTurn. Adapters no longer write the Preparation capability
that registration derives.

The local read-only preparation holds no resource, so delete its
always-nil Close, the preparationState.prepared closer, the read-only
cleanup_unconfirmed retry path and the handoff branches that
executor-less preparations never reach.

* Settle read-only preparation release synchronously

The read-only preparation holds no resource, so its release only drops
ownership. Drop it in the same state change instead of a cleanup
goroutine behind the busy flag, and delete closePreparationResource and
the shutdown close loop. A preparation that is still publishing its
readiness keeps ownership until that returns, as before.
# Conflicts:
#	Makefile
#	apps/daemon/internal/agent/claudesdk/declaration.go
#	apps/daemon/internal/agent/claudesdk/preparation_test.go
#	apps/daemon/internal/agent/codex/declaration.go
#	apps/daemon/internal/agent/codex/declaration_test.go
#	apps/daemon/internal/agent/codex/mcp_http_preflight_test.go
#	apps/daemon/internal/agent/codex/mcp_required_test.go
#	apps/daemon/internal/agent/codex/prepared.go
#	apps/daemon/internal/agent/codex/prepared_test.go
#	apps/daemon/internal/agent/codex/recovery_test.go
#	apps/daemon/internal/agent/configuration_test.go
#	apps/daemon/internal/agent/harness.go
#	apps/daemon/internal/agent/mcode/declaration.go
#	apps/daemon/internal/agent/registry.go
#	apps/daemon/internal/dispatch/local_directory.go
#	apps/daemon/internal/dispatch/preparation.go
#	apps/daemon/internal/dispatch/workspace_preparation_status_test.go
#	contracts/agents-api/harness-onboarding.md
#	contracts/agents-api/zh/harness-onboarding.md
#	contracts/agents-api/zh/index.md
#	docs/runtime-protocol.md
#	docs/zh/development.md
#	docs/zh/maintainers.md
#	docs/zh/runtime-protocol.md
# Conflicts:
#	apps/daemon/internal/agent/claudesdk/cancellation_live_linux_test.go
#	apps/daemon/internal/agent/claudesdk/contracts.go
#	apps/daemon/internal/agent/claudesdk/declaration_test.go
#	apps/daemon/internal/agent/claudesdk/execution_controls_test.go
#	apps/daemon/internal/agent/codex/contracts.go
#	apps/daemon/internal/agent/codex/execution_controls_test.go
#	apps/daemon/internal/agent/codex/preparation_router_test.go
#	apps/daemon/internal/agent/configuration_test.go
#	apps/daemon/internal/agent/contract_declarations_test.go
#	apps/daemon/internal/agent/mcode/contracts.go
#	apps/daemon/internal/agent/registry_test.go
#	apps/daemon/internal/cli/connect_cleanup_test.go
#	apps/daemon/internal/dispatch/capability_admission_test.go
#	apps/daemon/internal/dispatch/executor_cancel_receipt_test.go
#	apps/daemon/internal/dispatch/executor_handoff_test.go
#	apps/daemon/internal/dispatch/executor_test.go
#	apps/daemon/internal/dispatch/functions.go
#	apps/daemon/internal/dispatch/interaction_decisions.go
#	apps/daemon/internal/dispatch/mcp_http_test.go
#	apps/daemon/internal/dispatch/optional_interactions_test.go
#	apps/daemon/internal/dispatch/preparation.go
#	apps/daemon/internal/dispatch/preparation_executor_fixture_test.go
#	apps/daemon/internal/dispatch/preparation_start.go
#	apps/daemon/internal/dispatch/preparation_test.go
#	apps/daemon/internal/dispatch/prepared_handoff_test.go
#	apps/daemon/internal/dispatch/router.go
#	apps/daemon/internal/dispatch/router_test.go
#	apps/daemon/internal/dispatch/suspend.go
#	apps/daemon/internal/dispatch/workspace_read.go
#	apps/daemon/internal/wireconformance/wire_test.go
#	apps/daemon/testdata/onboarding/main.go
#	contracts/agents-api/harness-onboarding.md
#	contracts/agents-api/openapi.yaml
#	contracts/agents-api/zh/harness-onboarding.md
#	docs/runtime-protocol.md
#	docs/zh/getting-started/install.md
#	docs/zh/getting-started/operations.md
#	docs/zh/runtime-protocol.md
#	services/core/internal/api/handler.go
#	services/core/internal/runtimegateway/session.go
#	services/core/internal/runtimegateway/session_test.go
# Conflicts:
#	apps/daemon/internal/agent/codex/executor_native_test.go
#	services/core/internal/runtimegateway/session.go
# Conflicts:
#	apps/daemon/internal/dispatch/local_directory_test.go
#	apps/daemon/internal/dispatch/preparation.go
#	apps/daemon/internal/dispatch/preparation_start.go
#	apps/daemon/internal/dispatch/runtime_preparation_test.go
#	apps/daemon/internal/dispatch/workspace_export.go
#	apps/daemon/internal/dispatch/workspace_export_test.go
#	apps/daemon/internal/dispatch/workspace_write_test.go
Prepare now requires a model and provider, so the registered Claude SDK
and MCP bearer live tests failed before execution. Both now send a
ModelProvider built from their private key file at run time, as the other
live tests do. The Claude SDK test drops the ambient Anthropic credential
variables, and the MCP bearer test drops the native wrapper's provider
overrides and key variable, so each run uses only the Session's provider.
@SaladDay
SaladDay merged commit e3f4bcb into aos/cutover Oct 7, 2026
@SaladDay
SaladDay deleted the aos/cutover-sync-3 branch October 7, 2026 14:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant