Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -27,17 +27,17 @@ OAC_WEB_DEV_PROXY_TARGET=http://127.0.0.1:8091
# the browser bundle and must contain non-secret container names only.
# OAC_WEB_DOCKER_BACKEND_GUIDE=1
# OAC_WEB_DOCKER_DATABASE_CONTAINER=oac-web-smoke-db
# OAC_WEB_DOCKER_API_CONTAINER=agents-core-web-api
# OAC_WEB_DOCKER_DAEMON_CONTAINER=agents-core-web-daemon
# OAC_WEB_DOCKER_API_CONTAINER=oac-web-smoke-api
# OAC_WEB_DOCKER_DAEMON_CONTAINER=oac-web-smoke-daemon
# OAC_WEB_DOCKER_CORE_PORT=8091

# Optional local-only Docker connection recipe. This renders a copyable command;
# it never gives the browser Docker access or reads the credential file. Every
# value below is compiled into the browser bundle, so values must be non-secret.
# Enable only for the matching operator-controlled local stack.
# OAC_WEB_DOCKER_GUIDE=1
# OAC_WEB_DOCKER_IMAGE=agents-core-web-executor:2b34ea46-codex-0.153.4
# OAC_WEB_DOCKER_API_CONTAINER=agents-core-web-api
# OAC_WEB_DOCKER_IMAGE=oac-web-smoke-executor:2b34ea46-codex-0.153.4
# OAC_WEB_DOCKER_API_CONTAINER=oac-web-smoke-api
# OAC_WEB_DOCKER_USER=501:20
# OAC_WEB_DOCKER_CREDENTIALS_HOME_PATH=.oac/web-smoke/executor-key.json
# OAC_WEB_DOCKER_RUNTIME_HOME_PATH=.oac/web-smoke/executors
Expand Down
1 change: 0 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,6 @@ coverage/
go.work.sum
__pycache__/
*.pyc
/.parsar/
/config/
/logs/
/state/
Expand Down
2 changes: 1 addition & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -152,7 +152,7 @@ Use OpenAgentCore for public project branding. The canonical mark is `docs/asset

## OpenAgentCore name guard

`make check-names` scans tracked text for retired branding, settings and installed command names. Each exception in `scripts/name-allowlist.json` names a path glob, a regular expression and a reason.
`make check-names` scans tracked text for retired branding, GitHub organization, settings and installed command names. Each exception in `scripts/name-allowlist.json` names a path glob, a regular expression and a reason.

- An exception covers only its matched text: an allowed repository import cannot hide a retired setting elsewhere on the line.
- Keep exceptions narrow and explain the preserved contract or detection input.
Expand Down
2 changes: 1 addition & 1 deletion LICENSE
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
MIT License

Copyright (c) 2026 MiniMax-AI-Dev
Copyright (c) 2026 MiniMax-AI

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,7 @@ describe("deployment resources and Runtime", () => {
});
it("accepts any well-formed Runtime image name in the Runtime reference", async () => {
const digest = "b".repeat(64);
for (const runtime_ref of [`parsar-core-runtime@sha256:${digest}`, `oac-runtime@sha256:${digest}`, `custom-runtime@sha256:${digest}`]) {
for (const runtime_ref of [`oac-runtime@sha256:${digest}`, `custom-runtime@sha256:${digest}`]) {
vi.stubGlobal("fetch", vi.fn().mockResolvedValue(new Response(JSON.stringify({ ...manifest, runtime_ref }))));
expect((await distributionRuntime(new AbortController().signal)).microsandbox_ref).toBe(runtime_ref);
expect(isRuntimeReleaseField("microsandbox_ref", runtime_ref)).toBe(true);
Expand Down
12 changes: 6 additions & 6 deletions apps/web/src/lib/docker-guide-config.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -7,8 +7,8 @@ import {

const valid = {
OAC_WEB_DOCKER_GUIDE: "1",
OAC_WEB_DOCKER_IMAGE: "agents-core-web-executor:2b34ea46-codex-0.153.4",
OAC_WEB_DOCKER_API_CONTAINER: "agents-core-web-api",
OAC_WEB_DOCKER_IMAGE: "oac-web-smoke-executor:2b34ea46-codex-0.153.4",
OAC_WEB_DOCKER_API_CONTAINER: "oac-web-smoke-api",
OAC_WEB_DOCKER_USER: "501:20",
OAC_WEB_DOCKER_CREDENTIALS_HOME_PATH: ".oac/web-smoke/executor-key.json",
OAC_WEB_DOCKER_RUNTIME_HOME_PATH: ".oac/web-smoke/executors",
Expand Down Expand Up @@ -53,8 +53,8 @@ describe("local Docker guide configuration", () => {
const validBackend = {
OAC_WEB_DOCKER_BACKEND_GUIDE: "1",
OAC_WEB_DOCKER_DATABASE_CONTAINER: "oac-web-smoke-db",
OAC_WEB_DOCKER_API_CONTAINER: "agents-core-web-api",
OAC_WEB_DOCKER_DAEMON_CONTAINER: "agents-core-web-daemon",
OAC_WEB_DOCKER_API_CONTAINER: "oac-web-smoke-api",
OAC_WEB_DOCKER_DAEMON_CONTAINER: "oac-web-smoke-daemon",
OAC_WEB_DOCKER_CORE_PORT: "8091",
};

Expand All @@ -70,8 +70,8 @@ describe("local Docker backend guide configuration", () => {
it("accepts only non-secret container names and a loopback Core port", () => {
expect(loadLocalDockerBackendGuideProfile(validBackend)).toEqual({
databaseContainer: "oac-web-smoke-db",
apiContainer: "agents-core-web-api",
daemonContainer: "agents-core-web-daemon",
apiContainer: "oac-web-smoke-api",
daemonContainer: "oac-web-smoke-daemon",
corePort: 8091,
});
});
Expand Down
2 changes: 1 addition & 1 deletion example/parsar/LICENSE
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
MIT License

Copyright (c) 2026 MiniMax-AI-Dev
Copyright (c) 2026 MiniMax-AI

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
Expand Down
4 changes: 2 additions & 2 deletions internal/agentdaemon/proto/outbound.go
Original file line number Diff line number Diff line change
Expand Up @@ -46,8 +46,8 @@ type PromptRequestPayload struct {
// (Claude --resume session id, scratch dir).
ConversationID string `json:"conversation_id"`

// RunID is the Parsar agent_run id; mirrored back on every
// upstream frame via Envelope.ID.
// RunID is the ID of the Core Turn this prompt executes; mirrored
// back on every upstream frame via Envelope.ID.
RunID string `json:"run_id"`

// Input preserves ordered user messages and content.
Expand Down
2 changes: 1 addition & 1 deletion internal/runtimecrypto/cmd/emit-fixture/main.go
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@ func main() {
}

out := fixture{
Description: "Wire fixture for Parsar runtime credential envelope. " +
Description: "Wire fixture for the Runtime credential envelope. " +
"Recipient keypair is committed for test reproducibility. DO NOT use these " +
"keys in any other context. Wire format: NaCl SealAnonymous (X25519 + " +
"XSalsa20-Poly1305), nonce = BLAKE2b-24(ephPub || recipientPub).",
Expand Down
2 changes: 1 addition & 1 deletion internal/runtimecrypto/testdata/wire_v1.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"description": "Wire fixture for Parsar runtime credential envelope. Recipient keypair is committed for test reproducibility. DO NOT use these keys in any other context. Wire format: NaCl SealAnonymous (X25519 + XSalsa20-Poly1305), nonce = BLAKE2b-24(ephPub || recipientPub).",
"description": "Wire fixture for the Runtime credential envelope. Recipient keypair is committed for test reproducibility. DO NOT use these keys in any other context. Wire format: NaCl SealAnonymous (X25519 + XSalsa20-Poly1305), nonce = BLAKE2b-24(ephPub || recipientPub).",
"wire_format": "nacl_sealed_box_v1",
"recipient_public_key_b64": "kxmWMYeGYw4zwKGkoXBQUh3Ac6CCD0jUechNvXEwRSk=",
"recipient_private_key_b64": "6b/6ZGaX77mlq1Q/ZUZd/T67wNc9orIpSslluBMYXz8=",
Expand Down
3 changes: 2 additions & 1 deletion scripts/check-names.py
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,8 @@
r"(?i:parsar)|\bAGENTS_CORE_WEB_[A-Z][A-Z0-9_]*|\bAGENTS_API_[A-Z][A-Z0-9_]*|\bCORE_CONSOLE_[A-Z][A-Z0-9_]*"
r"|\bagents-api(?:-(?:migrate|device|environment-key|e2b-provider|microsandbox-provider"
r"|tool-root|codex-directory|codex-write|workspace-export|runtime-initialize|claude-shell-prefix))?\b"
r"|\bcore-console\b|\bagents-runtime-|(?i:\bAgents? Core(?: Web)?\b)|@agents-core-web/",
r"|\bcore-console\b|\bagents-runtime-|(?i:\bAgents? Core(?: Web)?\b)|@agents-core-web/"
r"|(?i:\bminimax-ai-dev\b)",
)


Expand Down
9 changes: 8 additions & 1 deletion scripts/check-names.test.py
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,8 @@ def test_detections_include_commands_settings_labels_and_display(self):
self.assertTrue(names.violations("x", value, []))

def test_new_names_and_pinned_public_contract_are_not_retired(self):
content = "OpenAgentCore oac-core OAC_CORE_PORT agents_api AgentCoreError x_agents_core core_console_session"
content = ("OpenAgentCore oac-core OAC_CORE_PORT agents_api AgentCoreError x_agents_core core_console_session"
" github.com/MiniMax-AI/OpenAgentCore")
self.assertFalse(names.violations("x", content, []))

def test_coordinates_and_multiple_matches_do_not_disclose_line_content(self):
Expand Down Expand Up @@ -126,6 +127,12 @@ def test_checked_in_exceptions_do_not_hide_unrelated_retired_setting(self):
with self.subTest(content=content):
self.assertEqual(len(names.violations("README.md", content, rules)), 1)

def test_retired_organization_is_rejected(self):
for content in ("Copyright (c) 2026 MiniMax-AI-Dev", "https://github.com/minimax-ai-dev/OpenAgentCore"):
with self.subTest(content=content):
self.assertEqual([item[2].lower() for item in names.violations("LICENSE", content, [])],
["minimax-ai-dev"])

def test_former_repository_identities_are_rejected(self):
rules = names.load_rules(Path(__file__).with_name("name-allowlist.json"))
for content in ("https://github.com/MiniMax-AI/parsar-core", '"github.com/MiniMax-AI-Dev/parsar/internal/foo"',
Expand Down
48 changes: 9 additions & 39 deletions scripts/name-allowlist.json
Original file line number Diff line number Diff line change
Expand Up @@ -16,8 +16,8 @@
},
{
"path": "*",
"regex": "Parsar (?:product|repository|service|checkout)\\b",
"reason": "These phrases explicitly refer to the separate Parsar product."
"regex": "Parsar product\\b",
"reason": "This phrase explicitly refers to the separate Parsar product."
},
{
"path": "packages/agents-client/v1/client.go",
Expand All @@ -31,18 +31,18 @@
},
{
"path": "scripts/name-allowlist.json",
"regex": "(?i)parsar|\\bAGENTS_CORE_WEB_[A-Z][A-Z0-9_]*|\\bAGENTS_API_[A-Z][A-Z0-9_]*|\\bCORE_CONSOLE_[A-Z][A-Z0-9_]*|\\bagents-api(?:-(?:migrate|device|environment-key|e2b-provider|microsandbox-provider|tool-root|codex-directory|codex-write|workspace-export|runtime-initialize|claude-shell-prefix))?\\b|\\bcore-console\\b|\\bagents-runtime-|\\bAgents? Core(?: Web)?\\b|@agents-core-web/",
"regex": "(?i)parsar|\\bAGENTS_CORE_WEB_[A-Z][A-Z0-9_]*|\\bAGENTS_API_[A-Z][A-Z0-9_]*|\\bCORE_CONSOLE_[A-Z][A-Z0-9_]*|\\bagents-api(?:-(?:migrate|device|environment-key|e2b-provider|microsandbox-provider|tool-root|codex-directory|codex-write|workspace-export|runtime-initialize|claude-shell-prefix))?\\b|\\bcore-console\\b|\\bagents-runtime-|\\bAgents? Core(?: Web)?\\b|@agents-core-web/|\\bminimax-ai-dev\\b",
"reason": "The reviewed guard policy must spell the names it explains; entries are checked for nonempty reasons."
},
{
"path": "scripts/check-names.test.py",
"regex": "(?i)parsar|\\bAGENTS_CORE_WEB_[A-Z][A-Z0-9_]*|\\bAGENTS_API_[A-Z][A-Z0-9_]*|\\bCORE_CONSOLE_[A-Z][A-Z0-9_]*|\\bagents-api(?:-(?:migrate|device|environment-key|e2b-provider|microsandbox-provider|tool-root|codex-directory|codex-write|workspace-export|runtime-initialize|claude-shell-prefix))?\\b|\\bcore-console\\b|\\bagents-runtime-|\\bAgents? Core(?: Web)?\\b|@agents-core-web/",
"regex": "(?i)parsar|\\bAGENTS_CORE_WEB_[A-Z][A-Z0-9_]*|\\bAGENTS_API_[A-Z][A-Z0-9_]*|\\bCORE_CONSOLE_[A-Z][A-Z0-9_]*|\\bagents-api(?:-(?:migrate|device|environment-key|e2b-provider|microsandbox-provider|tool-root|codex-directory|codex-write|workspace-export|runtime-initialize|claude-shell-prefix))?\\b|\\bcore-console\\b|\\bagents-runtime-|\\bAgents? Core(?: Web)?\\b|@agents-core-web/|\\bminimax-ai-dev\\b",
"reason": "Guard regression fixtures intentionally contain retired identifiers, including rejected examples."
},
{
"path": "*",
"regex": "\\bPARSAR_(?:CAPABILITY_UPLOAD_TOKEN|SERVER_URL|MASTER_KEY|PROTOCOL_BASELINE_REVISION)\\b",
"reason": "These four settings belong to the separate product integration; Core does not rename their protocol."
"path": "apps/daemon/internal/cli/skill_upload*.go",
"regex": "\\bPARSAR_(?:CAPABILITY_UPLOAD_TOKEN|SERVER_URL)\\b",
"reason": "These settings belong to the separate product capability upload integration; Core does not rename their protocol."
},
{
"path": "services/core/migrations/000078_oac_runtime_names.sql",
Expand All @@ -59,11 +59,6 @@
"regex": "https://developers\\.openai\\.com/api/docs/guides/agents-api(?:/[A-Za-z0-9_./-]*)?",
"reason": "Official upstream documentation URLs are external protocol references."
},
{
"path": ".gitignore",
"regex": "(?m)^/\\.parsar/$",
"reason": "Ignore legacy private state; it is not a supported installed command."
},
{
"path": "services/core/internal/credentialcrypto/*.go",
"regex": "parsar\\.agents-api\\.(?:agent-model-execution\\.v1|credential(?:-fingerprint\\.v1)?|deployment-model-provider\\.v1|environment-file|environment-setup|session-model-execution\\.v1|sandbox-deployment\\.v1|skill)",
Expand Down Expand Up @@ -149,11 +144,6 @@
"regex": "parsar-core-runtime@sha256:|parsar_worker /home/runtime/\\.parsar",
"reason": "Migration input and historical Session content assertions prove only the Runtime reference changes, never stored conversation data."
},
{
"path": "services/core/internal/store/environment_setup_test.go",
"regex": "PARSAR_APPLICATION_VALUE",
"reason": "This test proves the old reservation no longer blocks application-provided product variables."
},
{
"path": "services/core/migrations/000075_public_url_binding.sql",
"regex": "AGENTS_API_PUBLIC_URL",
Expand All @@ -179,29 +169,9 @@
"regex": "parsar(?:-server|\\.example\\.test)?|PARSAR_RUNNER_TOKEN",
"reason": "The dormant product capability upload/download integration locates the separate product CLI and checks its product credentials; it is explicitly retained."
},
{
"path": "internal/runtimecrypto/cmd/emit-fixture/main.go",
"regex": "Parsar runtime credential envelope",
"reason": "This deterministic historical wire fixture names the originating protocol; its bytes remain stable."
},
{
"path": "internal/runtimecrypto/testdata/wire_v1.json",
"regex": "Parsar runtime credential envelope",
"reason": "This deterministic historical wire fixture names the originating protocol; its bytes remain stable."
},
{
"path": "internal/agentdaemon/proto/outbound.go",
"regex": "Parsar agent_run id",
"reason": "The legacy field documents the originating product wire identifier; its JSON contract is unchanged."
},
{
"path": "apps/web/src/features/sandbox/deployment-specification.test.ts",
"regex": "parsar-core-runtime@sha256:",
"reason": "The literal is a rejected legacy Runtime prefix fixture, not an accepted deployment reference."
},
{
"path": "CONTRIBUTING.md",
"regex": "in Parsar\\.|apps/parsar/|Parsar is an ordinary client|Parsar integration|Parsar owns|`parsar` provider slug",
"regex": "apps/parsar/|Parsar owns",
"reason": "These exact phrases refer to the separate Parsar product, its ownership or historical source, not the OpenAgentCore brand."
},
{
Expand All @@ -216,7 +186,7 @@
},
{
"path": "apps/web/.impeccable/surfaces/src-app-tsx.md",
"regex": "Parsar [Ii]ndigo|Parsar\\n",
"regex": "Parsar indigo",
"reason": "The design records explicitly attribute the copied indigo palette to its original product; it is not a rendered Core product label."
},
{
Expand Down
1 change: 0 additions & 1 deletion services/core/cmd/server/credential_cipher_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,6 @@ import (

func TestCredentialCipherConfiguration(t *testing.T) {
t.Setenv("OAC_CREDENTIAL_KEY_FILE", "")
t.Setenv("PARSAR_MASTER_KEY", "must-not-be-used")
if c, err := credentialCipher(); c != nil || err != nil {
t.Fatal("absent dedicated key must remain disabled", err)
}
Expand Down
2 changes: 1 addition & 1 deletion services/core/internal/store/environment_setup_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -93,7 +93,7 @@ func TestEnvironmentSetupReservesOpenAgentCoreNames(t *testing.T) {
t.Fatalf("reserved name %s accepted: %v", name, err)
}
}
if err := (EnvironmentSetup{Env: map[string]string{"APPLICATION_VALUE": "ok", "PARSAR_APPLICATION_VALUE": "product"}}).Validate(); err != nil {
if err := (EnvironmentSetup{Env: map[string]string{"APPLICATION_VALUE": "ok"}}).Validate(); err != nil {
t.Fatalf("ordinary application settings rejected: %v", err)
}
}
Loading