Require explicit Runtime and Harness capability contracts - #256
Merged
Merged
Conversation
SaladDay
marked this pull request as ready for review
September 30, 2026 06:23
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Runtime capability omissions previously looked like unsupported features, and optional Go interface presence could grant behavior without an explicit declaration. Require a deliberate Supported/Unsupported decision for every capability, reject incomplete registration and heartbeat declarations, and admit operations against their owner's frozen declaration. Future fields and public adapter interfaces must be accounted for explicitly.
Codex, Claude Code and MiniMax Code now explicitly implement the public Harness interfaces. Required lifecycle, durable input, cancellation, settlement and close obligations remain real. Unsupported extensions return typed errors without native effects; a claimed operation that is absent or rejects its contract is reported as a contract violation. Shared workspace composition and public API, model and MCP authority semantics remain unchanged.
The private daemon protocol advances to 0.11.0 while retaining explicit JSON booleans. Core and daemon must match exactly; this adds no historical compatibility or upgrade path. Resource allocation and Executor lifetimes remain separate.
Validation
Final candidate:
30a2f28a78c030bcef8644e86aa8caeb11966dc9, including the Provider contract from #255.make check-sandbox-provider-contract check-runtime-contract: passed.3a4ad5fd: no substantiated in-scope findings.65cfa71b; daemon, adapter, shared wire and bridge source is unchanged in the final candidate. Tests cover reuse, cancellation, cleanup and the supported recovery behavior of each adapter.Scope and limits
Live evidence is Linux self-hosted; it does not qualify public HTTP MCP or managed Docker/E2B deployment. macOS/Windows evidence is native CI for currently supported combinations; MiniMax Code remains unsupported on Windows. No deployment, release or tag is included. Acceptance processes were stopped; their databases, workspaces and history were preserved.