Declare agent-host Session views in the Runtime–Harness protocol - #350
Merged
Merged
Conversation
SaladDay
force-pushed
the
aos/view-declaration
branch
from
October 1, 2026 02:14
1bbb307 to
3984693
Compare
Runtime gains a View declaration: closure mounts, overlays, masks, the local exec allowlist, shims, forwarded variables, the proxy mode and a view Executor factory. View.Validate checks it without touching the host, Registry.RegisterView records it with configuration validation, and ResolveView returns it or wraps ErrUnsupportedOperation. Codex, Claude and MiniMax declare View: nil, and the declaration test requires the field in every adapter. clirunner.Process gains a handle-backed constructor, FromHandle, and an ExitCode accessor; Codex reads the exit through the accessor. The sessionview Spec takes a StagingParent instead of the system temporary directory, and exports PrivateRoot and ShimDir for the declaration. Harness onboarding documents the View field, RegisterView and running in an agent-host view.
Cancelling a handle-backed process that has ended does nothing, so the handle is not closed before Wait drains output, and Handle.Close never closes the stdio ends the Process owns. Wait closes stdin, stdout, stderr and the handle once, and returns the context error when cancellation interrupted a process that then exited 0, keeping the exit code, as exec.CommandContext does.
The agent host resolves the Session's MCP once, from the public declarations and the installed Environment MCP, into ViewSession.MCP. HTTP bindings point at the gateway with no bearer and no headers, the request carries no MCP, and the registered view factory rejects a session or request that breaks this. harness.go is the one definition of the view layout: ViewPrivateRoot, the bin, home and run names, /proc, /dev and ViewReserved. sessionview imports it and drops its own constants, and agent no longer imports sessionview. ForwardEnv rejects the variables the view or broker sets, including proxy variables in any case, and the tool environment wins over a forwarded variable. A view signal reaches every process in the view, and when the process exits while others remain, the launcher sends them TERM and waits up to Process.Grace before it exits.
Declaration.ConnectionOptions marks the AgentOptions keys that carry MCP, endpoints, credentials or environment values; Codex and MiniMax mark mcp_servers and env. The view Executor wrapper checks once, before the factory, that the prepared model provider is the loopback gateway with the placeholder key, that no connection option is set and that MCP arrives only credential-free in ViewSession.MCP, and returns ErrViewHandoff otherwise. Handle.Signal reports a process that has exited with os.ErrProcessDone, so a cancel marks the process interrupted only when its TERM reached the running process. sessionview tracks the Harness's exit apart from the drain: the launcher acknowledges each signal and delivers none once the Harness is reaped, View.Signal then returns ErrExited, and the drain keeps the grace remaining since an earlier TERM without sending a second one.
This was referenced Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Lane L5p of the agent-outside-sandbox workstream. It is a Runtime–Harness protocol change: a Harness declares how it runs in an agent-host Session view. Its loop runs on the agent host, its file and process operations go to the sandbox, and its model and MCP traffic goes through the Session gateway. Every adapter declares
View: nilin this PR; the adapter lanes fill it in.Protocol (
apps/daemon/internal/agent/harness.go,registry.go)Runtime.View *View:ViewProxyEnvorViewProxyNone, with an invalid zero value);ViewExecutorFactorythat receives aViewSession(home, proxy andLaunch).View.Validate()checks a declaration without touching the host, and an invalid declaration givesErrInvalidView.Registry.RegisterViewvalidates the view and wraps its factory soPrepareruns first, like the other factories.Registry.ResolveViewreturns a copy. A kind without a view givesErrUnsupportedOperation; an unknown kind givesErrUnsupportedKind.TestPublicHarnessContractDeclarationsrequires every declaration to stateViewexplicitly.Supporting changes
clirunner:Handle,HandleOptionsandFromHandleprovide a handle-backed process. Cancel sends TERM, then closes the handle afterKillTimeout.Process.ExitCode()is the exit-status accessor, so Codex no longer readsexec.Cmd.sessionview:Spec.StagingParentis required, an existing absolute directory, with no temp-dir fallback.PrivateRootandShimDirare exported.harness-onboarding.md:RegisterView.Checks
Blind review fixes
Two blind review rounds; their fixes are in the three follow-up commits.
LocalEnvironment.MCP, and passes it inViewSession.MCP: HTTP bindings at gateway URLs with no credentials.Declaration.ConnectionOptionsmarks native options that carry connections (Codex and MiniMax:mcp_servers,env). The view rejects them withErrViewHandoff.modelprovider.Placeholder.ForwardEnvrejects proxy variables and names the view owns (HOME,PATH,TMPDIR,LANG,LD_LIBRARY_PATH).harness.go(ViewPrivateRoot,ViewShimName,ViewHomeName,ViewRunName,ViewReserved).sessionviewimports it, andagentno longer importssessionview.Waitcloses stdin, stdout and stderr once.exec.CommandContextdoes.View.Signalreaches every process in the view. When the leader exits, remaining processes get one TERM, never a second one, and the remaining grace.