Skip to content

Require explicit Runtime and Harness capability contracts - #256

Merged
SaladDay merged 13 commits into
mainfrom
codex/explicit-runtime-capabilities-20260930
Sep 30, 2026
Merged

SaladDay merged 13 commits into
mainfrom
codex/explicit-runtime-capabilities-20260930

Conversation

@SaladDay

@SaladDay SaladDay commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Runtime capability omissions previously looked like unsupported features, and optional Go interface presence could grant behavior without an explicit declaration. Require a deliberate Supported/Unsupported decision for every capability, reject incomplete registration and heartbeat declarations, and admit operations against their owner's frozen declaration. Future fields and public adapter interfaces must be accounted for explicitly.

Codex, Claude Code and MiniMax Code now explicitly implement the public Harness interfaces. Required lifecycle, durable input, cancellation, settlement and close obligations remain real. Unsupported extensions return typed errors without native effects; a claimed operation that is absent or rejects its contract is reported as a contract violation. Shared workspace composition and public API, model and MCP authority semantics remain unchanged.

The private daemon protocol advances to 0.11.0 while retaining explicit JSON booleans. Core and daemon must match exactly; this adds no historical compatibility or upgrade path. Resource allocation and Executor lifetimes remain separate.

Validation

Final candidate: 30a2f28a78c030bcef8644e86aa8caeb11966dc9, including the Provider contract from #255.

  • Combined remote make check-sandbox-provider-contract check-runtime-contract: passed.
  • Native Linux, Windows and macOS CI: passed.
  • Official-client acceptance: passed.
  • Full make check: passed.
  • Fresh independent review of the final complete diff against 3a4ad5fd: no substantiated in-scope findings.
  • Linux real-model native lifecycle tests passed for Codex 0.153.4, Claude SDK 0.3.269 / native 2.1.269, and MiniMax Code 0.4.12, all using MiniMax-M2.7. These ran at 65cfa71b; daemon, adapter, shared wire and bridge source is unchanged in the final candidate. Tests cover reuse, cancellation, cleanup and the supported recovery behavior of each adapter.
  • Newly built final-candidate Core and daemon passed public self-hosted Skill/Plugin stdio MCP preparation and execution, daemon cold reconnect, and unchanged capability snapshot reuse for all three Harnesses. Codex used Responses; Claude and MiniMax Code used Anthropic. Claude's first attempt failed because the model changed to the Skill directory and wrote the artifact there; that record is retained. A fresh Session with an explicit workspace command passed both turns with unchanged assertions.

Scope and limits

Live evidence is Linux self-hosted; it does not qualify public HTTP MCP or managed Docker/E2B deployment. macOS/Windows evidence is native CI for currently supported combinations; MiniMax Code remains unsupported on Windows. No deployment, release or tag is included. Acceptance processes were stopped; their databases, workspaces and history were preserved.

@SaladDay
SaladDay marked this pull request as ready for review September 30, 2026 06:23
@SaladDay
SaladDay merged commit 0be2e10 into main Sep 30, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant