Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
20 commits
Select commit Hold shift + click to select a range
8063859
feat: install Core on Linux, macOS and Windows through one workflow (…
SaladDay Oct 7, 2026
9ede935
Delete the direct-call Harness factory (#484)
SaladDay Oct 7, 2026
80dfaea
ci: split code and docs reviews with one Feishu report (#485)
SaladDay Oct 7, 2026
addf285
fix(ci): retain completed reviews within the execution timeout (#487)
SaladDay Oct 7, 2026
516fd30
Run Harnesses unattended and delete the interaction protocol (#489)
SaladDay Oct 7, 2026
0a0328c
Bound the Link relay's resources, attachments, closures and pending d…
SaladDay Oct 7, 2026
2bb8edc
Merge remote-tracking branch 'origin/main' into aos/main-sync-2
SaladDay Oct 7, 2026
a02ff8e
fix(ci): restore structured Feishu review cards (#492)
SaladDay Oct 7, 2026
87e0480
Fix agent tests after merging main
SaladDay Oct 7, 2026
b6482b8
Merge main into the agent-outside-sandbox branch (#494)
SaladDay Oct 7, 2026
3c71473
Mirror the native matrix sentence in zh maintainers (#495)
SaladDay Oct 7, 2026
1fcc066
refactor(api): generate public contracts from official OpenAPI (#490)
SaladDay Oct 7, 2026
17ec052
refactor(api): trim schema generation and unify text types (#497)
SaladDay Oct 7, 2026
939e0c4
Delete the adapter Prepared path (#498)
SaladDay Oct 7, 2026
e4c1ed6
Merge remote-tracking branch 'origin/main' into aos/main-sync-3
SaladDay Oct 7, 2026
7bba93a
Delete the mcode opt-in and dead helpers (#499)
SaladDay Oct 7, 2026
8e16621
Merge branch 'aos/main-sync-3' into aos/cutover-sync-3
SaladDay Oct 7, 2026
0107af1
Merge remote-tracking branch 'origin/main' into aos/main-sync-3
SaladDay Oct 7, 2026
1da8795
Merge branch 'aos/main-sync-3' into aos/cutover-sync-3
SaladDay Oct 7, 2026
855f6de
Send the Session's model provider in two live tests
SaladDay Oct 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
1 change: 1 addition & 0 deletions .github/workflows/api-acceptance.yml
Original file line number Diff line number Diff line change
Expand Up @@ -62,6 +62,7 @@ jobs:
OAC_TEST_SERVER_BIN: ${{ runner.temp }}/oac-core-build/oac-core
OAC_TEST_OFFICIAL_SDK_PYTHON: python
run: |
python services/core/tests/official_schema_test.py
python services/core/tests/official_client.py
go test ./services/core/tests/integration -run '^(TestFunctionStateOfficialClientReadsAndLiveEvents|TestSavedReferenceRetryOfficialClient|TestAgentUpdateOfficialClient|TestAgentDeletionOfficialClient|TestSessionAgentFilterOfficialClient|TestSessionDeletionOfficialClient|TestEnvironmentInitialFailureOfficialClient|TestSelfHostedInitialCreationOfficialClient|TestSelfHostedCancellationOfficialClient)$' -count=1
- uses: ./.github/actions/e2b-provider
Expand Down
19 changes: 17 additions & 2 deletions .github/workflows/check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -184,15 +184,30 @@ jobs:
compose:
needs: plan
if: needs.plan.result == 'success' && contains(fromJSON(needs.plan.outputs.jobs || '[]'), 'compose')
runs-on: ${{ vars.OAC_USE_GITHUB_RUNNERS == 'true' && 'ubuntu-22.04' || 'blacksmith-2vcpu-ubuntu-2204' }}
timeout-minutes: 20
strategy:
fail-fast: false
matrix:
include:
- runner: ubuntu-24.04
architecture: amd64
- runner: ubuntu-24.04-arm
architecture: arm64
runs-on: ${{ matrix.runner }}
env:
GOARCH: ${{ matrix.architecture }}
timeout-minutes: 30
steps:
- uses: actions/checkout@v7
with:
ref: ${{ inputs.ref || github.sha }}
- uses: actions/setup-go@v7
with:
go-version-file: go.mod
- name: Test the native Core installation lifecycle
run: go test ./services/core/cmd/oac -count=1 -timeout=3m
- uses: ./.github/actions/e2b-provider
- name: Build and verify the architecture-matched E2B helper
run: bash scripts/build-e2b-provider.sh
- name: Allocate an isolated Compose project
run: python3 -c 'import uuid; print("COMPOSE_SMOKE_PROJECT=oac-smoke-" + uuid.uuid4().hex)' >> "$GITHUB_ENV"
- name: Build the images, start the installation and verify it
Expand Down
103 changes: 74 additions & 29 deletions .github/workflows/ci-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,12 +16,28 @@ permissions:

jobs:
review:
name: ${{ matrix.name }}
strategy:
fail-fast: false
matrix:
include:
- kind: code
name: Code review
instructions: |
检查本次代码改动的正确性、仓库设计规则及已有 CI 结果。先读取 AGENTS.md 和 CONTRIBUTING.md,再查看相关实现和测试。
用 gh pr checks 查询这个 PR 已有的检查结果,必要时读取 Actions 日志。检查失败、缺失或尚未完成时如实报告,不把合并当作检查通过的证据。
报告包括实际行为变化(1–3 条)、代码审查结论和 CI 状态。全部正常时保持简短;有问题时给出文件与行号、证据和最小修改建议。
- kind: docs
name: Docs review
instructions: |
每次都检查文档与本次代码变化是否一致,即使 PR 没改文档。读取相关实现、测试和完整文档,核对平台、命令、配置、路径、默认值、接口和操作流程,找出遗漏更新或已经过时的说明。
文档有修改(包括新增、删除和重命名)时,再检查文档内部及同主题文档间的矛盾、重复维护的事实、主题归属和中英文含义。按 AGENTS.md 和 CONTRIBUTING.md 的 Documentation ownership 表判断位置。必要的概述加链接、中英文对照和同一来源生成的文档不算重复。
分别报告“文档与代码一致性”和“文档矛盾、重复与归属”。未改文档时,第二项写“本次未修改文档”。只报告本次修改引入或使之过时的、有依据的问题,给出文件与行号、对应代码或文档依据,以及最小修改建议。测试或链接检查通过不代表语义一致。只报告影响读者理解或操作的具体问题,不把未穷举实现细节当作文档缺陷。
if: github.event.pull_request.merged == true
runs-on: ${{ vars.OAC_USE_GITHUB_RUNNERS == 'true' && 'ubuntu-24.04' || 'blacksmith-2vcpu-ubuntu-2404' }}
timeout-minutes: 30
env:
# allowed_non_write_users turns on a subprocess secret scrub; opt out so Claude's
# commands can read GH_TOKEN and the Feishu webhook.
# Keep GH_TOKEN available to read the PR and Actions logs.
CLAUDE_CODE_SUBPROCESS_ENV_SCRUB: '0'
steps:
# The triggering revision is already on main, so its rules and code are trusted.
Expand All @@ -30,14 +46,15 @@ jobs:
ref: ${{ github.event.pull_request.merge_commit_sha }}
fetch-depth: 2
persist-credentials: false
- name: Review and send Feishu card with Claude Code
# Notification is best effort: a failed review or delivery never fails the job.
- name: Prepare the report schema
id: schema
run: python3 scripts/ci_review.py schema "${{ matrix.kind }}" >> "$GITHUB_OUTPUT"
- name: Review with Claude Code
id: llm
continue-on-error: true
timeout-minutes: 25
uses: anthropics/claude-code-action@12dd8d74c712f5f3669365b2369b558c495b1104 # v1
env:
FEISHU_WEBHOOK_URL: ${{ secrets.FEISHU_WEBHOOK_URL }}
FEISHU_WEBHOOK_SECRET: ${{ secrets.FEISHU_WEBHOOK_SECRET }}
ANTHROPIC_BASE_URL: https://api.minimax.cn/anthropic
ANTHROPIC_AUTH_TOKEN: ${{ secrets.MINIMAX_API_KEY }}
CLAUDE_CODE_AUTO_COMPACT_WINDOW: '524288'
Expand All @@ -54,29 +71,57 @@ jobs:
allowed_bots: '*'
allowed_non_write_users: '*'
prompt: |
你是 CI 的负责人,负责审核 CI 结果并给出结论。
仓库 ${{ github.repository }} 的 PR #${{ github.event.pull_request.number }} 已合入 main:
- PR:https://github.com/${{ github.repository }}/pull/${{ github.event.pull_request.number }}
- 合并 commit:${{ github.event.pull_request.merge_commit_sha }}(已 checkout 到当前目录)

用 gh pr checks ${{ github.event.pull_request.number }} --repo ${{ github.repository }} 查询这个 PR 已有的检查结果,必要时读取对应 Actions 日志。不要触发新的 CI,也不要把合并本身当作检查通过的证据;管理员可能绕过门禁。检查失败、缺失或尚未完成时如实报告。
你负责本次 PR 的 ${{ matrix.name }},在独立上下文中完成审查。
仓库:${{ github.repository }};PR:#${{ github.event.pull_request.number }}。
合并提交:${{ github.event.pull_request.merge_commit_sha }},已检出到当前目录。
先用 gh pr diff ${{ github.event.pull_request.number }} --repo ${{ github.repository }} 读取变更清单与完整差异,再检查相关文件。

任务:给飞书群发一张中文卡片(Card 2.0)总结这次 CI,尽量在 10 轮以内给出结论,工具调用尽可能的并行。
环境里有 gh(已登录,GH_TOKEN)、git、node 和完整的仓库代码。
${{ matrix.instructions }}

卡片要让手机上的读者快速看懂,如果一切正常,表达的尽可能简单,如果没有问题,尽量简洁:
1. 哪个 PR(github id + PR 标题 + 链接)
- 如:`github id: jing332, PR 标题: 添加一个新功能, 链接: https://github.com/org/repo/pull/123`
2. 改了什么(实际行为变化,1–3 条)
- 如:`添加了一个新功能、修改了 web 和 backend 的 CI`
3. 是否符合仓库规则(AGENTS.md、CONTRIBUTING.md 及相关文档):未发现明确违规 / 发现需修复问题 / 信息不足,无法确认
- 如:`符合仓库规则`
4. CI 哪里失败、可能的原因(可以看日志),全部通过就直接说通过,不要给出细节。如果 CI 失败,则详细说明。
- 如:`CI 失败,具体是哪几个失败;全部通过 ✅`

发送:webhook 地址在环境变量 FEISHU_WEBHOOK_URL。
响应 code=0 才算成功,失败就排查并重试,直到发出去。最后用一句中文说明结果,如:`CI 结果已发送至飞书群`。
不要在输出里打印 webhook 地址和密钥。
按 JSON schema 返回中文报告。status 为 ok(未发现问题)、issues(发现有证据的问题)或 incomplete(审查失败、范围未检查完整或检查结果尚未完成)。有问题且仍有未检查项时,用 issues 并在对应字段中说明缺项。按 schema 把各项结论分别填入字段,不要重复标题;changes 用 1–3 条 Markdown 列表,其他字段无问题时一句话,有问题时保留依据和建议,遵守各字段长度限制。
围绕本次 diff 和受影响的文档展开,证据充分后输出结果,避免重复核对同一结论。
只读审查,不修改仓库,不触发新的 CI,不发送消息。两份报告会由后续 job 合并发送。
claude_args: >-
--allowedTools Bash Read Write Edit Glob Grep WebFetch WebSearch
--max-turns 30
--allowedTools Bash Read Glob Grep
--json-schema '${{ steps.schema.outputs.schema }}'
- name: Save the review result
if: always()
env:
REVIEW_OUTCOME: ${{ steps.llm.outcome }}
REVIEW_RESULT: ${{ steps.llm.outputs.structured_output }}
run: python3 scripts/ci_review.py collect "${{ matrix.kind }}" "$RUNNER_TEMP/review-${{ matrix.kind }}.json"
- uses: actions/upload-artifact@v6
if: always()
with:
name: ci-review-${{ matrix.kind }}
path: ${{ runner.temp }}/review-${{ matrix.kind }}.json
if-no-files-found: error
overwrite: true
retention-days: 7

notify:
name: Combined Feishu notification
needs: review
if: always() && github.event.pull_request.merged == true
runs-on: ${{ vars.OAC_USE_GITHUB_RUNNERS == 'true' && 'ubuntu-24.04' || 'blacksmith-2vcpu-ubuntu-2404' }}
timeout-minutes: 5
permissions:
contents: read
actions: read
steps:
- uses: actions/checkout@v7
with:
ref: ${{ github.event.pull_request.merge_commit_sha }}
persist-credentials: false
- uses: actions/download-artifact@v6
continue-on-error: true
with:
pattern: ci-review-*
merge-multiple: true
path: ${{ runner.temp }}/reviews
- name: Send one card with both results
continue-on-error: true
env:
FEISHU_WEBHOOK_URL: ${{ secrets.FEISHU_WEBHOOK_URL }}
FEISHU_WEBHOOK_SECRET: ${{ secrets.FEISHU_WEBHOOK_SECRET }}
run: python3 scripts/ci_review.py notify "$RUNNER_TEMP/reviews"
22 changes: 22 additions & 0 deletions .github/workflows/native.yml
Original file line number Diff line number Diff line change
Expand Up @@ -63,6 +63,14 @@ jobs:
run: |
go build -ldflags "-X github.com/MiniMax-AI/OpenAgentCore/apps/daemon/internal/cli.Version=$(git rev-parse HEAD)" -o "$RUNNER_TEMP/oac-daemon${{ runner.os == 'Windows' && '.exe' || '' }}" ./apps/daemon/cmd/oac-daemon
node --test scripts/build-native-installer.test.mjs
- name: Build and test the shared Core installer
run: |
go build -o "$RUNNER_TEMP/oac${{ runner.os == 'Windows' && '.exe' || '' }}" ./services/core/cmd/oac
go test ./services/core/cmd/oac -count=1 -timeout=3m
- name: Exercise the Windows Core launcher
if: runner.os == 'Windows'
shell: pwsh
run: ./deploy/test_install.ps1 -Binary "$env:RUNNER_TEMP/oac.exe"
- name: Verify native download bootstrap and recovery
run: go test ./services/core/internal/nativeinstaller -count=1 -timeout=3m
- name: Native filesystem, authentication and process lifecycle
Expand Down Expand Up @@ -163,3 +171,17 @@ jobs:
path: ${{ runner.temp }}/native-ci-diagnostics/
retention-days: 7
if-no-files-found: ignore

core-intel-mac:
name: Core installer (macOS Intel)
runs-on: macos-15-intel
timeout-minutes: 10
steps:
- uses: actions/checkout@v7
with:
ref: ${{ inputs.ref || github.sha }}
- uses: actions/setup-go@v7
with:
go-version-file: go.mod
- run: go test ./services/core/cmd/oac -count=1 -timeout=3m
- run: go build -o "$RUNNER_TEMP/oac" ./services/core/cmd/oac
7 changes: 5 additions & 2 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -114,6 +114,9 @@ jobs:
path: ${{ runner.temp }}/native-artifacts
- name: Assemble the native installation catalog
run: node scripts/build-native-catalog.mjs "$RUNNER_TEMP/native-artifacts" "$RUNNER_TEMP/native-installers"
- uses: docker/setup-qemu-action@v3
with:
platforms: arm64
- uses: ./.github/actions/e2b-provider
- name: Build matched artifacts
env:
Expand All @@ -133,8 +136,8 @@ jobs:
for asset in "$HOME/.oac/build/core-distribution/"*; do
if [[ -f "$asset" ]]; then ln "$asset" "$HOME/.oac/build/release-upload/"; fi
done
cp deploy/install.sh "$HOME/.oac/build/release-upload/install.sh"
(cd "$HOME/.oac/build/release-upload" && sha256sum install.sh > install.sh.sha256)
cp deploy/install.sh deploy/install.ps1 "$HOME/.oac/build/release-upload/"
(cd "$HOME/.oac/build/release-upload" && sha256sum install.sh > install.sh.sha256 && sha256sum install.ps1 > install.ps1.sha256)
- name: Sign in to GHCR
if: github.event_name == 'push' || inputs.draft_release
env:
Expand Down
2 changes: 1 addition & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ Do not multiply entities without necessity. The long-term goal is minimal code,

| Boundary | Protocol code | Protocol doc |
| --- | --- | --- |
| Application–Core (`/v1`) | Types in `contracts/agents-api/v1/` and route annotations in `services/core/internal/api/`; `make openapi` generates `contracts/agents-api/openapi.yaml` | [Agents API guide](docs/api/public-agent-api.md) |
| Application–Core (`/v1`) | Official schema pinned by `contracts/agents-api/upstream.json` plus Go-owned `x_agents_core` extensions; `make openapi` generates public Go types and `contracts/agents-api/openapi.yaml` | [Agents API guide](docs/api/public-agent-api.md) |
| Web and operators–Core (`/core/v1`) | Route annotations in `services/core/internal/api/`; `make openapi` generates `contracts/agents-api/core.openapi.yaml` | [Core administration API](contracts/agents-api/admin-api.md) |
| Nodes and daemons–Core (`/api/v1` HTTP routes; the node and daemon wire protocols are separate rows) | Route annotations in `services/core/internal/api/`; `make openapi` generates `contracts/agents-api/runtime.openapi.yaml` | [Machine connection API](contracts/agents-api/machine-api.md) |
| Core–Sandbox Provider | `services/core/internal/sandbox/sandbox_provider.go` | [Sandbox Provider guide](docs/sandbox-provider.md) |
Expand Down
17 changes: 12 additions & 5 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -32,21 +32,28 @@ sqlc-generate:

SWAG ?= go run github.com/swaggo/swag/cmd/swag@$(SWAG_VERSION)

.PHONY: openapi
.PHONY: openapi check-openapi
OPENAPI_FLAGS ?=
check-openapi:
$(MAKE) openapi OPENAPI_FLAGS=--check
python3 scripts/generate-public-api.test.py

openapi:
@set -e; root="$${OAC_DEV_HOME:-$$HOME/.oac}/build"; mkdir -p "$$root"; \
output=$$(mktemp -d "$$root/core-openapi.XXXXXX"); trap 'rm -rf "$$output"' EXIT; \
python3 scripts/generate-public-api.py $(OPENAPI_FLAGS) --swag-roots "$$output/roots.go"; \
$(SWAG) init \
-g cmd/server/main.go --dir ./services/core,./contracts/agents-api/v1 \
-g cmd/server/main.go --dir "./services/core,./contracts/agents-api/v1,$$output" \
--output "$$output" \
--outputTypes yaml --parseInternal; \
python3 scripts/patch-agents-openapi.py "$$output/swagger.yaml"; \
go run ./scripts/openapi-split "$$output/swagger.yaml" contracts/agents-api/openapi.yaml contracts/agents-api/core.openapi.yaml contracts/agents-api/runtime.openapi.yaml
go run ./scripts/openapi-split $(OPENAPI_FLAGS) "$$output/swagger.yaml" "$$output/extensions.json" contracts/agents-api/core.openapi.yaml contracts/agents-api/runtime.openapi.yaml; \
python3 scripts/generate-public-api.py $(OPENAPI_FLAGS) --extensions "$$output/extensions.json"

check-sqlc:
python3 scripts/check-sqlc.py

check-go:
check-go: check-openapi
go test ./apps/daemon/... ./apps/sandboxio/... ./internal/... ./contracts/agents-api/... ./scripts/openapi-split -count=1

.PHONY: check-runtime-contract
Expand Down Expand Up @@ -183,7 +190,7 @@ check-microsandbox-provider:
.PHONY: check-distribution build-core-distribution
check-distribution:
node --test scripts/build-native-catalog.test.mjs
go test ./services/web -count=1
go test ./services/web ./services/core/cmd/oac -count=1
PYTHONDONTWRITEBYTECODE=1 python3 -m unittest discover -s deploy/node -p 'test_*.py'
PYTHONDONTWRITEBYTECODE=1 python3 -m unittest discover -s deploy/compose -p 'test_*.py'
PYTHONDONTWRITEBYTECODE=1 python3 -m unittest discover -s scripts/acceptance -p 'test_*.py'
Expand Down
8 changes: 7 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -42,12 +42,18 @@ Core keeps durable execution state. The Runtime runs the chosen harness inside t

## Install

On a Linux amd64 host with Docker and Python 3.9+:
On Linux or macOS with [Docker configured](https://openagentcore.dev/docs/getting-started/install#prerequisites):

```sh
curl -fsSL https://github.com/MiniMax-AI/OpenAgentCore/releases/latest/download/install.sh | bash
```

Windows PowerShell:

```powershell
irm https://github.com/MiniMax-AI/OpenAgentCore/releases/latest/download/install.ps1 | iex
```

Then:

1. **Sign in to Web**, the admin console, with the Core key the installer created, and **configure the domain and HTTPS**.
Expand Down
8 changes: 7 additions & 1 deletion README.zh-CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -42,12 +42,18 @@ OpenAgentCore 在你自己的基础设施上运行 AI Agent,对外提供 [Open

## 安装

在已准备 Docker 和 Python 3.9+ 的 Linux amd64 主机上:
在已按[前置条件](https://openagentcore.dev/zh/docs/getting-started/install#prerequisites)准备 Docker 的 Linux 或 macOS 上:

```sh
curl -fsSL https://github.com/MiniMax-AI/OpenAgentCore/releases/latest/download/install.sh | bash
```

Windows PowerShell:

```powershell
irm https://github.com/MiniMax-AI/OpenAgentCore/releases/latest/download/install.ps1 | iex
```

然后:

1. 用安装器生成的 Core key **登录 Web**(管理控制台),并**配置域名和 HTTPS**。
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -67,7 +67,7 @@ func TestLiveClaudeSDKCancelResume(t *testing.T) {
defer cancel()
out := make(chan proto.Envelope, 64)
request := proto.PromptRequestPayload{RunID: uuid.NewString(), Input: proto.TextInput(prompt), AgentSessionID: resume, ObserveMessages: true, DisableExecutionEnvironment: true, DisableSubagents: true, ExecutionControls: &proto.ExecutionControls{WebSearch: "disabled", TextVerbosity: "medium"}, Model: "MiniMax-M3", ModelProvider: provider, SystemPrompt: "Follow the user's requested format. Preserve the exact verification value in conversation history. Use no tools."}
running, err := NewFactory(config)(ctx, request, out)
running, err := startSingleTurn(ctx, config, request, out)
if err != nil {
t.Fatal(err)
}
Expand Down
Loading
Loading